IT

Tracker / CVE-2018-6514

CVE-2018-6514

High 7.8

In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a DLL preloading attack, which could lead to a privilege escalation.

Affected products and versions

puppet puppet · 1.10.0 → 1.10.13
puppet puppet · 5.3.0 → 5.3.7
puppet puppet · 5.5.0 → 5.5.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References